These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges.
CVSS Vector
AV:N/AC:L/Au:N/C:C/I:C/A:NSinapsitech Esolar Duo Photovoltaic System Monitor
HWSinapsitechall versionsSinapsitech Esolar Light Photovoltaic System Monitor
HWSinapsitechall versionsSinapsitech Esolar Photovoltaic System Monitor
HWSinapsitechall versionsSinapsitech Sinapsi Firmware
OSSinapsitech≤ 2.0.2870
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
References
Related vulnerabilities
CVE-2012-5861HIGH7.8same product
These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL ta...
CVE-2012-5862HIGH10.0same product
These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passw...
CVE-2012-5863HIGH10.0same product
These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain ...